Skip to content

Azure backup

Azure backup outside the Microsoft control plane

Microsoft runs your Azure tenant. Mindtime runs your recovery plan: immutable copies of Azure workloads, Microsoft 365 data and Entra ID configuration, held in Dutch and German data centres under EU law.

Works with
Azure Backup
Covers
Azure · Microsoft 365 · Entra ID
Data centres
NL · DE
Jurisdiction
EU only

In short

What is Azure backup?

Sovereign Azure backup is an independent copy of your Azure workloads, held outside the Microsoft perimeter by a European operator. If your tenant, admin account or region becomes unavailable, the backups don't go with it. Mindtime keeps them immutable in the Netherlands and Germany.

What we back up
Azure VMs, disks, Files, Blob, SQL, Cosmos DB, AKS volumes, Microsoft 365 and Entra ID
Where it is stored
Mindtime data centres in the Netherlands and Germany, outside Azure
How it is protected
WORM-enforced and air-gapped by default, with an identity plane separate from Entra ID
Encryption keys
Customer-held or EU-HSM keys

The risk

Azure Backup isn't an independent strategy

Recovery Services Vaults and geo-redundant storage live inside the same Microsoft control plane you need protection from.

  1. Entra ID

    A single point of failure

    Compromise a Global Admin or lose the tenant, and the vault holding your backups is compromised or locked at the same moment.

  2. CLOUD Act

    Residency isn't sovereignty

    Your data can sit in West Europe, but Microsoft is a US company and the CLOUD Act still applies.

  3. Gaps

    Overlapping retention

    Exchange, SharePoint, OneDrive, Teams and Entra ID each have their own retention rules, and none of them is a backup.

What's covered

Azure, Microsoft 365 and the identity tier beneath them

The Microsoft stack is connected. Protect only part of it, and recovery fails at the wrong moment.

  • VM

    Azure infrastructure

    • VMs and managed disks
    • Azure Files and Blob
    • Azure SQL, SQL MI, PostgreSQL and MySQL Flexible Server
    • Cosmos DB and AKS volumes
  • M365

    Microsoft 365 data

    • Exchange Online mailboxes
    • SharePoint and OneDrive
    • Teams chats, channels and files
    • Item-level restore
  • ID

    Entra ID and configuration

    • Users, groups and roles
    • Conditional access policies
    • App registrations
    • Rebuild a tenant, not only files

What's included

How Mindtime protects it

Standard with every Mindtime backup, on top of the 3-2-1-1-0 rule and immutable storage in the Netherlands and Germany.

  • Immutable by default

    WORM-enforced storage. Backups can't be changed or deleted during retention.

  • Separate control plane

    Backups sit behind credentials and an identity plane that are separate from Microsoft Entra ID and Azure, so one compromised admin can't reach both.

  • Your keys

    Bring your own keys or use an EU-based HSM. Your data is cryptographically yours.

  • EU end to end

    EU legal entity, EU staff and EU sub-processors, with no US parent company.

  • Verified recoveries

    Quarterly restore drills with signed reports for your auditors.

  • Evidence for regulators

    Evidence for DORA and NIS2 audits, plus a GDPR Data Processing Agreement.

The difference

Azure Backup vs. Mindtime

Native tools are a good first copy. An independent backup is the one you can still reach when the first copy is gone.

Azure Backup vs. Mindtime
CapabilityAzure Backup (native)Mindtime sovereign backup
Legal jurisdictionUS, CLOUD Act appliesEU only: contract, operator and storage
Identity planeMicrosoft Entra IDIndependent, separate from Entra ID
Storage locationAzure Recovery Services VaultsMindtime data centres in NL and DE, outside Azure
ImmutabilitySoft delete and immutable vaultsWORM-enforced, air-gapped by default
Encryption keysMicrosoft-managed or CMK in Key VaultCustomer-held or EU-HSM keys
Works with Azure Backup—Yes: we complement it, we don't replace it

How it works

Up and running in three steps

No rip-and-replace and no long project. Our team helps you at every step.

  1. 01

    Consultation and scoping

    A 45-minute call about your Azure tenant, Microsoft 365 footprint, recovery targets and regulators such as DORA and NIS2.

  2. 02

    Architecture and deployment

    We design the sovereign vault, set immutable policies and deploy with least-privilege app registrations and Graph API scopes.

  3. 03

    Verified recoveries

    Quarterly restore drills, signed reports for your auditors, and a named European engineer on your account.

FAQ

Common questions

Do we have to stop using Azure Backup or Microsoft 365 retention?

No. Keep native tools for fast rollbacks inside the tenant. Mindtime is the sovereign, immutable copy held outside Microsoft's control plane.

Is Microsoft 365 data really not backed up?

Retention policies, litigation hold and recycle bins are not backup. They can be changed or overridden by the same credentials that may have caused the incident.

What about the EU Data Boundary and Microsoft's sovereign cloud?

They are meaningful controls on where data is stored and processed. They don't remove Microsoft's obligations under the US CLOUD Act. Jurisdictional independence needs an EU-only operator.

How fast can we recover an entire tenant?

We design to your recovery time objective, including Entra ID configuration and Microsoft 365 dependencies, and prove it in quarterly drills.